<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:circular="https://rhnvrm.github.io/stock-market-circulars/ns"><channel><title>Cyber-Audit - Stock Market Circulars</title><link>https://rhnvrm.github.io/stock-market-circulars/tags/cyber-audit/</link><description>Regulatory circulars from NSE, BSE, and SEBI with AI-powered summaries</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 15 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://rhnvrm.github.io/stock-market-circulars/tags/cyber-audit/feed.xml" rel="self" type="application/rss+xml"/><item><title>Periodic Submission of System, Cyber, and VAPT Audit by Application Service Providers (ASP)</title><link>https://rhnvrm.github.io/stock-market-circulars/circulars/bse/2026/bse-2026-05-15-445c4c0405a981be-periodic-submission-of-system-cyber-and-vapt-audit-by-application-service-provid/</link><pubDate>Fri, 15 May 2026 12:55:41 +0000</pubDate><guid>https://rhnvrm.github.io/stock-market-circulars/circulars/bse/2026/bse-2026-05-15-445c4c0405a981be-periodic-submission-of-system-cyber-and-vapt-audit-by-application-service-provid/</guid><description>BSE mandates registered ASP vendors to conduct and submit periodic System Audit, Cyber Security Audit, and VAPT assessments annually, with reports due by 30th June and Action Taken Reports by 30th September.</description><circular:source>bse</circular:source><circular:category>compliance</circular:category><circular:impact>medium</circular:impact><circular:severity>medium</circular:severity><circular:importance>medium</circular:importance><circular:id>445c4c0405a981be</circular:id><circular:pdfUrl>https://www.bseindia.com/downloads/UploadDocs/Notices/20260515-23/20260515-23.pdf</circular:pdfUrl><category>asp</category><category>system-audit</category><category>cyber-audit</category><category>vapt</category><category>cybersecurity</category><category>compliance</category><category>trading-operations</category><category>application-service-provider</category><category>sebi-cscrf</category><category>audit-report</category><content:encoded><![CDATA[<h2 id="summary">Summary</h2>
<p>BSE has issued guidelines requiring all registered Application Service Providers (ASPs) to conduct and submit periodic System Audit, Cyber Security Audit, and Vulnerability Assessment and Penetration Testing (VAPT) on a yearly basis. The audits cover the audit period 1st April to 31st March, with audit reports due by 30th June and Action Taken Reports (ATRs) due by 30th September each year.</p>
<h2 id="key-points">Key Points</h2>
<ul>
<li>All registered ASPs must conduct periodic system audits of their Non-Exchange Trading Frontend and security controls.</li>
<li>Cyber Security Audit and VAPT assessments are required annually to strengthen cybersecurity resilience against incidents and attacks.</li>
<li>Three audit types are mandated: System Audit Report, Cyber Audit Report, and VAPT Report — all covering the period 1st April to 31st March.</li>
<li>Audit reports must be submitted on or before 30th June; Action Taken Reports (if applicable) must be submitted on or before 30th September.</li>
<li>All audit reports must be approved by the Managing Director, Director, CTO, or CISO before submission.</li>
<li>Detailed guidelines, formats, and Terms of Reference (TOR) are provided via seven annexures (A through G).</li>
</ul>
<h2 id="regulatory-changes">Regulatory Changes</h2>
<p>No new regulatory framework is introduced; this notice consolidates and reiterates existing cybersecurity compliance obligations for ASP vendors, aligning with SEBI&rsquo;s Cyber Security and Cyber Resilience Framework (SEBI CSCRF). Formats for VAPT audit reports and auditor declarations are now standardized per SEBI CSCRF requirements.</p>
<h2 id="compliance-requirements">Compliance Requirements</h2>
<ul>
<li>Registered ASP vendors must select auditors per the norms in Annexure A.</li>
<li>System Audit and Cyber Audit reports must follow formats in Annexure B and Annexure C respectively.</li>
<li>VAPT audit submissions must include: Auditor&rsquo;s Declaration (Annexure D) and VAPT Summary Report (Annexure E).</li>
<li>System Audit must follow the Terms of Reference (TOR) in Annexure F; Cyber Audit must follow TOR in Annexure G.</li>
<li>All three audit reports require sign-off from MD/Director/CTO/CISO before submission to BSE.</li>
<li>Contact for queries: <a href="mailto:trading.app@bseindia.com">trading.app@bseindia.com</a> / <a href="mailto:mscopr@bseindia.com">mscopr@bseindia.com</a>; Phone: 022-22725116/5873/8926/5376.</li>
</ul>
<h2 id="important-dates">Important Dates</h2>
<ul>
<li><strong>Audit Period:</strong> 1st April to 31st March (annual)</li>
<li><strong>Audit Report Submission Deadline:</strong> On or before 30th June</li>
<li><strong>Action Taken Report (ATR) Submission Deadline:</strong> On or before 30th September</li>
</ul>
<h2 id="impact-assessment">Impact Assessment</h2>
<p>This circular directly impacts registered ASP vendors providing trading frontend services on BSE. It imposes structured, time-bound audit obligations with standardized formats and escalated approval requirements (MD/CTO/CISO sign-off). Non-compliance could result in regulatory action against the ASP&rsquo;s registration status. The broader market impact is limited as this targets infrastructure providers rather than trading members or investors directly; however, it strengthens the cybersecurity posture of the trading ecosystem.</p>
]]></content:encoded></item></channel></rss>